CVE-2026-90396: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: block: fix dio leak on metadata mapping error A failed integrity mapping holds a dio reference, so we need to go through the full bio ending in case there were previously submitted bio's in the sequence.

Affected products

  • Linux Linux: from 6.16.8, before 6.17 (fixed in 6.17); from 6.17, before 6.18.52 (fixed in 6.18.52); from 6.19, before 7.2.6 (fixed in 7.2.6)

Published 2026-09-17. Last modified 2026-09-17.